What Claude Code's Leaked Source Reveals About AI Agent Governance
Dev.to AI
•
Generative AI
On March 31, 2026, security researcher Chaofan Shou discovered that Anthropic had accidentally shipped the complete source code of Claude Code in their npm package. A.map file contained a link to 1,900 TypeScript files - 512,000 lines of unobfuscated source. Within hours, the community mirrored it on GitHub (1,100+ stars, 1,900+ forks). Anthropic pushed an update to remove the maps, but the code was already public. This is their second major leak in five days. The source code itself is interesting but not groundbreaking. What's far significant is what the unreleased feature flags reveal.